Vendor
Nvidia vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 194 vulnerabilities in Nvidia: 19 in the last 7 days and 145 in the last 90 days, 11 of them critical and 0 exploited in the wild. The most recent, CVE-2026-65179, was published on 22 September 2026. 20 technologies have a page of their own.
- Last 7 days
- 19
- Last 90 days
- 145
- Critical, all time
- 11
- Exploited in the wild
- 0
About Nvidia
NVIDIA is a technology company that designs and manufactures graphics processing units (GPUs) and computing hardware.
Nvidia technologies
- Nvidia Megatron-Bridge43
- Nvidia NeMo Megatron Bridge32
- Nvidia Triton Inference Server25
- Nvidia Dynamo15
- Nvidia TensorRT-LLM13
- Nvidia Nemoclaw12
- Nvidia Display Driver7
- Nvidia Dynamo for Linux7
- Nvidia Display Driver for Linux6
- Nvidia Dgx Spark5
- Nvidia Dgx Spark Uefi5
- Nvidia TensorRT5
- Nvidia Tesla5
- Nvidia UFM Enterprise5
- Nvidia DALI3
- Nvidia Jetson Linux3
- Nvidia NeMo Framework3
- Nvidia Nemo Speech3
- Nvidia OpenShell for Linux3
- Nvidia TRT-LLM3
Latest Nvidia vulnerabilities
- CVE-2026-65179: NVIDIA NeMo unsafe pickle deserialization in TabularTokenizerhighCVSS 8.8EPSS 0.7%
- CVE-2026-65178: NVIDIA NeMo unsafe parameter injection in model_config.yamlhighCVSS 7.8EPSS 0.4%
- CVE-2026-65130: NVIDIA Infrastructure Controller for Linux OS command injectionhighCVSS 8EPSS 2.1%
- CVE-2026-65129: NVIDIA Infrastructure Controller for Linux improper certificate validationmediumCVSS 6.7EPSS 0.1%
- CVE-2026-65128: NVIDIA Infrastructure Controller for Linux SQL injectionhighCVSS 8.8EPSS 0.6%
- CVE-2026-65127: NVIDIA Infrastructure Controller for Linux information disclosure in debug logsmediumCVSS 4.1EPSS 0.2%
- CVE-2026-65126: NVIDIA Infrastructure Controller for Linux behavioral workflow enforcementmediumCVSS 5EPSS 0.3%
- CVE-2026-65125: NVIDIA Infrastructure Controller for Linux path traversalmediumCVSS 6.6EPSS 0.6%
- CVE-2026-65124: NVIDIA Infrastructure Controller for Linux XML injectionmediumCVSS 5.9EPSS 0.5%
- CVE-2026-65121: NVIDIA Infrastructure Controller for Linux authentication bypasshighCVSS 8.2EPSS 0.3%
- CVE-2026-65118: NVIDIA Infrastructure Controller for Linux improper certificate validationhighCVSS 7.5EPSS 0.1%
- CVE-2026-65117: NVIDIA Infrastructure Controller for Linux hard-coded passwordmediumCVSS 5EPSS 0.2%
- CVE-2026-65115: NVIDIA Infrastructure Controller for Linux resource exhaustionmediumCVSS 6.5EPSS 0.5%
- CVE-2026-65114: NVIDIA Infrastructure Controller for Linux missing authenticationhighCVSS 8.3EPSS 0.4%
- CVE-2026-65113: NVIDIA Infrastructure Controller for Linux hard-coded credentials vulnerabilitycriticalCVSS 9.8EPSS 0.6%
- CVE-2026-65112: NVIDIA Infrastructure Controller for Linux resource exhaustionmediumCVSS 6.5EPSS 0.5%
- CVE-2026-65111: NVIDIA NeMo Speech code injection vulnerabilityhighCVSS 7.8EPSS 0.2%
- CVE-2026-24267: NVIDIA NeMo Speech remote code execution in data explorerhighCVSS 7.8EPSS 0.3%
- CVE-2026-24239: NVIDIA NeMo Speech remote code execution from malicious datahighCVSS 7.8EPSS 0.3%
- CVE-2026-16140: OpenBMC phosphor-net-ipmid privilege escalation in RAKP authenticationhighCVSS 8.8EPSS 0.3%
- CVE-2026-47625: NVIDIA Triton Inference Server authorization bypasshighCVSS 7.5EPSS 0.6%
- CVE-2026-16497: NVIDIA Triton Inference Server excessive iteration denial of servicehighCVSS 7.5EPSS 0.5%
- CVE-2026-61779: NVIDIA Megatron Bridge deserialization vulnerabilityhighCVSS 7.8EPSS 0.4%
- CVE-2026-61778: NVIDIA Megatron Bridge deserialization of untrusted datahighCVSS 7.8EPSS 0.4%
- CVE-2026-61777: NVIDIA Megatron Bridge unsafe deserializationhighCVSS 7.8EPSS 0.4%
Most severe Nvidia vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-65083: NVIDIA OpenShell for Linux incomplete input allowlist in sandbox provisioning APIcriticalCVSS 9.9EPSS 0.9%
- CVE-2026-65093: NVIDIA OpenShell for Linux sandbox escapecriticalCVSS 9.9EPSS 0.8%
- CVE-2026-24254: NVIDIA Dynamo for Linux out-of-bounds write in multimodal serving topologycriticalCVSS 9.8EPSS 0.9%
- CVE-2026-47627: NVIDIA Triton Inference Server path traversalcriticalCVSS 9.8EPSS 0.7%
- CVE-2026-53805: NVIDIA GEN3C remote code execution in inference API servercriticalCVSS 9.8EPSS 0.7%
- CVE-2026-65113: NVIDIA Infrastructure Controller for Linux hard-coded credentials vulnerabilitycriticalCVSS 9.8EPSS 0.6%
- CVE-2026-24178: NVIDIA NVFlare Dashboard authorization bypass in user management systemcriticalCVSS 9.8EPSS 0.6%
- CVE-2026-24270: NVIDIA AIStore framework authentication bypasscriticalCVSS 9.8
- CVE-2026-24207: NVIDIA Triton Inference Server authentication bypasscriticalCVSS 9.8
- CVE-2025-23351: NVIDIA ConnectX and BlueField out-of-bounds write in command interfacecriticalCVSS 9
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 17 | 3 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 23 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 2 | 0 | |
| 3 Aug 2026 | 16 | 1 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 8 | 1 | |
| 24 Aug 2026 | 26 | 2 | |
| 31 Aug 2026 | 30 | 0 | |
| 7 Sep 2026 | 2 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 19 | 1 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/nvidia.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Nvidia vulnerabilities", https://junglewise.ai/threats/vendors/nvidia, 26 September 2026.